{"id":"GHSA-47w6-gwp4-w6vc","title":"vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review","summary":"vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review","severity":"high","cwe":["CWE-863"],"vendor":"vantage6","product":"vantage6","ecosystem":"pip","affected":["vantage6 <= 5.0.2"],"published":"2026-07-24","updated":"2026-07-24","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-47w6-gwp4-w6vc","references":[{"url":"https://github.com/vantage6/vantage6/security/advisories/GHSA-47w6-gwp4-w6vc"},{"url":"https://github.com/advisories/GHSA-47w6-gwp4-w6vc"}],"tags":["ghsa","pip"],"ingestedAt":"2026-07-24T22:40:26.958Z","slug":"GHSA-47w6-gwp4-w6vc","body":"## Overview\n\n### Impact\nEdit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes. \n\nWorst they could do is update the image or image tag. If that is not noted, another image is approved than the one actually under review\n\n### Patches\nNo\n\n### Workarounds\nNo\n\n## Affected packages\n\n- `vantage6 <= 5.0.2`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}